Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> the exception is already bad for iPhone security

It objectively is. Safari is a weak spot in the iPhone security.

https://www.cvedetails.com/cve/CVE-2023-42890/ https://www.cvedetails.com/cve/CVE-2023-42917/ https://www.cvedetails.com/cve/CVE-2023-42916/

Three vulnerabilities that involve visiting a webpage, and all are due to the W^X exception I mentioned. Something that users do very often, unlike with installing an app. Apple also can't remove webpages from the internet, it can remove apps. It doesn't scan webpages before they're published, it does this with apps. A webpage can have an advert, which is loaded from a different server. A webpage can redirect you to another webpage run by another company, without user confirmation. Etc.

> or just solve these iOS challenges to make every web browser more secure

That comes at a cost though. Increased battery usage, memory usage, and slower web browsing. As I explained, there is a setting called Lockdown Mode which enables this, but it's a user choice.

> how come macOS is just fine with fully capable web browsers?

Well macOS is less secure than iOS - and Safari is a weak point on macOS as well - but users also don't expect it to be as secure. For example I expect that apps can read data of other apps on the desktop, but on the phone there is a separation enforced. There is a clause in the DMA for Apple to maintain security which is their justification for Notarization and some other stuff that isn't done on desktop.

Also macOS started in 2001 and has been basically backwards compatible since then, if it started in 2010 like the iPhone then it would be a lot different in terms of the security architecture.

You are being very argumentative and hostile without understanding what I'm saying, which I don't appreciate because I was just trying to answer your question about security.



I see that you had high level replies and you are probably more knowledgable than I am in security.

However, you cannot shut down browsers because they are the weak spot.

Even if you are right in every argument you wrote in security I do not find it relevant.

You have the choice to use Safari on iOS and your security will not be worse than before.

I just believe that freedom and choice is trumping this kind of parenting security.

Again, everybody can remove browsers or not use them or use Safari or shut down js.

We can grow and evolve, browsers could blacklists or whitelist sites, you can use these lists or not...

I really dont understand the fearmongering.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: